First published: Wed Apr 12 2000(Updated: )
IIS 4.0 and 5.0 allows remote attackers to cause a denial of service by sending many URLs with a large number of escaped characters, aka the "Myriad Escaped Characters" Vulnerability.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Information Services | =4.0 | |
Microsoft Internet Information Services (IIS) | =5.0 | |
=4.0 | ||
=5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0258 is classified as a denial of service vulnerability affecting IIS 4.0 and 5.0.
To mitigate CVE-2000-0258, it is recommended to upgrade to a newer version of IIS that is not vulnerable to this issue.
CVE-2000-0258 affects Microsoft Internet Information Server 4.0 and Internet Information Services 5.0.
Yes, CVE-2000-0258 can lead to server downtime by causing denial of service through excessive requests.
There are no known workarounds for CVE-2000-0258 other than updating the affected software.